Cmdlet that applies a policy definition (-PolicyDefinition) at a chosen scope (-Scope, for example a resource group's ResourceId). To change an assignment that already exists, use Set-AzPolicyAssignment.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains New-AzPolicyAssignment in context, with comparison tables and the common traps.
Terms in this definition
- Policy definition
A JSON rule expressing a compliance condition as if/then logic with an effect, plus parameters and metadata. Nothing happens until it is assigned, and the category it carries is purely metadata.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Resource group
Container for Azure resources. Its location holds only metadata and cannot be changed afterwards, and one resource group cannot sit inside another.
- Set-AzPolicyAssignment
PowerShell cmdlet in Az for changing a policy assignment that already exists, such as its identity or display name. Creating a new assignment uses New-AzPolicyAssignment.
Related terms
- Get-AzPolicyDefinition
Cmdlet in Az.Resources that fetches a policy definition, for instance using
-Name, so it can be handed toNew-AzPolicyAssignment.